Total
395739 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-81207 | 1 Ibm | 1 Datastage On Cloud Pak For Data | 2026-09-16 | N/A | 8.5 HIGH |
| IBM DataStage on Cloud Pak for Data 5.4.0.0 allows any authenticated tenant — with no project membership or role — fully controls scheme/host/port/path of an outbound fetch originating from a shared-infrastructure pod, and the WSDL body is reflected verbatim to the caller. The ds-canvas pod sits on the OpenShift overlay with reach to co-tenant services, in-cluster CP4D APIs, and link-local addresses. Scope is Changed, confidentiality High (response-reflecting), integrity Low (GET-only side-effects). | |||||
| CVE-2026-81540 | 1 Ibm | 1 Datastage On Cloud Pak For Data | 2026-09-16 | N/A | 8.5 HIGH |
| IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to overwrite ruleset files belonging to other tenants due to a path traversal vulnerability. | |||||
| CVE-2026-81550 | 1 Ibm | 1 Datastage On Cloud Pak For Data | 2026-09-16 | N/A | 8.8 HIGH |
| IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command. | |||||
| CVE-2026-81554 | 1 Ibm | 1 Datastage On Cloud Pak For Data | 2026-09-16 | N/A | 8.8 HIGH |
| IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an absolute-path traversal vulnerability. | |||||
| CVE-2026-81551 | 1 Ibm | 1 Datastage On Cloud Pak For Data | 2026-09-16 | N/A | 8.8 HIGH |
| IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to arbitrarily write to or delete files on shared storage due to a path traversal vulnerability. | |||||
| CVE-2026-82092 | 1 Ibm | 1 Datastage On Cloud Pak For Data | 2026-09-16 | N/A | 8.8 HIGH |
| IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an absolute-path traversal vulnerability. | |||||
| CVE-2026-82095 | 1 Ibm | 1 Datastage On Cloud Pak For Data | 2026-09-16 | N/A | 8.8 HIGH |
| IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command. | |||||
| CVE-2026-82097 | 1 Ibm | 1 Datastage On Cloud Pak For Data | 2026-09-16 | N/A | 8.8 HIGH |
| IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to a Server-Side Request Forgery (SSRF) vulnerability. | |||||
| CVE-2026-82098 | 1 Ibm | 1 Datastage On Cloud Pak For Data | 2026-09-16 | N/A | 8.8 HIGH |
| IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. | |||||
| CVE-2026-82099 | 1 Ibm | 1 Datastage On Cloud Pak For Data | 2026-09-16 | N/A | 8.8 HIGH |
| IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command. | |||||
| CVE-2026-82100 | 1 Ibm | 1 Datastage On Cloud Pak For Data | 2026-09-16 | N/A | 9.6 CRITICAL |
| IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service due to a path traversal vulnerability. | |||||
| CVE-2026-82107 | 1 Ibm | 1 Datastage On Cloud Pak For Data | 2026-09-16 | N/A | 9.6 CRITICAL |
| IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information and bypass security restrictions due to improper authentication. | |||||
| CVE-2026-92257 | 2026-09-15 | N/A | 5.4 MEDIUM | ||
| Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in L7 content management pages that use eval() sinks, affecting the call board text and policy group handling components. Attackers can inject persistent script payloads through these pages to have malicious code executed in the context of other users viewing the affected content. | |||||
| CVE-2026-92255 | 2026-09-15 | N/A | 5.4 MEDIUM | ||
| Netcore NR255-V version 1.5.130703 contains an out-of-bounds read vulnerability in filter_arp_put_file.cgi caused by improper use of a string handling API. Attackers can trigger an unterminated buffer over-read by exploiting this flaw in the affected component, potentially exposing adjacent memory contents. | |||||
| CVE-2026-10150 | 2026-09-15 | N/A | N/A | ||
| Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |||||
| CVE-2026-10149 | 2026-09-15 | N/A | N/A | ||
| Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |||||
| CVE-2026-10145 | 2026-09-15 | N/A | N/A | ||
| Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |||||
| CVE-2026-10144 | 2026-09-15 | N/A | 7.8 HIGH | ||
| Rsbuild before 2.0.9 contains a command injection vulnerability that allows attackers to execute arbitrary OS commands by supplying a crafted URL containing shell metacharacters to the server.open configuration on macOS. The openBrowser() function in packages/core/src/server/open.ts passes the URL through encodeURI() before interpolating it into a shell command executed via child_process.exec(), but because encodeURI() does not encode dollar signs, parentheses, or semicolons, embedded shell metacharacters are evaluated by /bin/sh, enabling arbitrary command execution. | |||||
| CVE-2026-43664 | 1 Apple | 5 Ipados, Iphone Os, Macos and 2 more | 2026-09-15 | N/A | 5.5 MEDIUM |
| This issue was addressed with improved data protection. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, watchOS 27. An app may be able to access sensitive user data. | |||||
| CVE-2026-91143 | 2026-09-15 | N/A | 7.2 HIGH | ||
| goproxy through 15.3 fails to apply HTTP proxy basic authentication to CONNECT tunnel requests, allowing unauthenticated clients to bypass credential requirements. Attackers can issue CONNECT requests to establish tunnels through the authenticated proxy without providing credentials, enabling arbitrary TCP traffic relay and access to restricted destinations. | |||||
